Search CVE reports


Toggle filters

221 – 230 of 881 results


CVE-2018-1999010

Medium priority

Some fixes available 1 of 50

FFmpeg before commit cced03dd667a5df6df8fd40d8de0bff477ee02e8 contains multiple out of array access vulnerabilities in the mms protocol that can result in attackers accessing out of bound data. This attack appear to be exploitable...

7 affected packages

chromium-browser, ffmpeg, gst-libav1.0, oxide-qt, qtwebengine-opensource-src...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser Ignored Ignored Not in release Ignored
ffmpeg Not affected Not affected Not affected Not affected
gst-libav1.0 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
oxide-qt Not in release Not in release Not in release Not in release
qtwebengine-opensource-src Needs evaluation Needs evaluation Needs evaluation Needs evaluation
vlc Not affected Not affected Not affected Not affected
libav Not in release Not in release Not in release Not in release
Show all 7 packages Show less packages

CVE-2018-13305

Medium priority
Needs evaluation

In FFmpeg 4.0.1, due to a missing check for negative values of the mquant variable, the vc1_put_blocks_clamped function in libavcodec/vc1_block.c may trigger an out-of-array access while converting a crafted AVI file to MPEG4,...

7 affected packages

vlc, gst-libav1.0, mythtv, libav, oxide-qt...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
vlc Not affected Not affected Not affected Not affected
gst-libav1.0 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
mythtv Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libav Not in release Not in release Not in release Not in release
oxide-qt Not in release Not in release Not in release Not in release
ffmpeg Not affected Not affected Not affected Not affected
chromium-browser Ignored Ignored Not in release Ignored
Show all 7 packages Show less packages

CVE-2018-13304

Medium priority
Needs evaluation

In libavcodec in FFmpeg 4.0.1, improper maintenance of the consistency between the context profile field and studio_profile in libavcodec may trigger an assertion failure while converting a crafted AVI file to MPEG4, leading to a...

12 affected packages

chromium-browser, kino, mplayer, dvbcut, gst-libav1.0...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser Ignored Ignored Not in release Ignored
kino Not in release Needs evaluation Needs evaluation Needs evaluation
mplayer Not affected Not affected Not affected Not affected
dvbcut Needs evaluation Needs evaluation Needs evaluation Needs evaluation
gst-libav1.0 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
mythtv Needs evaluation Needs evaluation Needs evaluation Needs evaluation
gstreamer0.10-ffmpeg Not in release Not in release Not in release Not in release
xine-lib Not in release Not in release Not in release Not in release
vlc Not affected Not affected Not affected Not affected
ffmpeg Not affected Not affected Not affected Not affected
libav Not in release Not in release Not in release Not in release
oxide-qt Not in release Not in release Not in release Not in release
Show all 12 packages Show less packages

CVE-2018-13303

Low priority
Needs evaluation

In FFmpeg 4.0.1, a missing check for failure of a call to init_get_bits8() in the avpriv_ac3_parse_header function in libavcodec/ac3_parser.c may trigger a NULL pointer dereference while converting a crafted AVI file to MPEG4,...

10 affected packages

chromium-browser, ffmpeg, gst-libav1.0, kino, mythtv...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser Ignored Ignored Not in release Ignored
ffmpeg Not affected Not affected Not affected Not affected
gst-libav1.0 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
kino Not in release Needs evaluation Needs evaluation Needs evaluation
mythtv Needs evaluation Needs evaluation Needs evaluation Needs evaluation
gstreamer0.10-ffmpeg Not in release Not in release Not in release Not in release
libav Not in release Not in release Not in release Not in release
oxide-qt Not in release Not in release Not in release Not in release
mplayer Not affected Not affected Not affected Not affected
vlc Not affected Not affected Not affected Not affected
Show all 10 packages Show less packages

CVE-2018-13302

Medium priority

Some fixes available 16 of 82

In FFmpeg 4.0.1, improper handling of frame types (other than EAC3_FRAME_TYPE_INDEPENDENT) that have multiple independent substreams in the handle_eac3 function in libavformat/movenc.c may trigger an out-of-array access while...

10 affected packages

chromium-browser, ffmpeg, gst-libav1.0, kino, mythtv...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser Ignored Ignored Not in release Ignored
ffmpeg Fixed Fixed Fixed Fixed
gst-libav1.0 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
kino Not in release Needs evaluation Needs evaluation Needs evaluation
mythtv Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libav Not in release Not in release Not in release Not in release
gstreamer0.10-ffmpeg Not in release Not in release Not in release Not in release
mplayer Not affected Not affected Not affected Not affected
oxide-qt Not in release Not in release Not in release Not in release
vlc Not affected Not affected Not affected Not affected
Show all 10 packages Show less packages

CVE-2018-13301

Low priority
Needs evaluation

In FFmpeg 4.0.1, due to a missing check of a profile value before setting it, the ff_mpeg4_decode_picture_header function in libavcodec/mpeg4videodec.c may trigger a NULL pointer dereference while converting a crafted AVI file to...

9 affected packages

chromium-browser, libav, gstreamer0.10-ffmpeg, vlc, gst-libav1.0...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser Ignored Ignored Not in release Ignored
libav Not in release Not in release Not in release Not in release
gstreamer0.10-ffmpeg Not in release Not in release Not in release Not in release
vlc Not affected Not affected Not affected Not affected
gst-libav1.0 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
mythtv Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ffmpeg Not affected Not affected Not affected Not affected
mplayer Not affected Not affected Not affected Not affected
oxide-qt Not in release Not in release Not in release Not in release
Show all 9 packages Show less packages

CVE-2018-13300

Medium priority

Some fixes available 15 of 81

In FFmpeg 3.2 and 4.0.1, an improper argument (AVCodecParameters) passed to the avpriv_request_sample function in the handle_eac3 function in libavformat/movenc.c may trigger an out-of-array read while converting a crafted AVI...

10 affected packages

chromium-browser, ffmpeg, gstreamer0.10-ffmpeg, mplayer, vlc...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser Ignored Ignored Not in release Ignored
ffmpeg Fixed Fixed Fixed Fixed
gstreamer0.10-ffmpeg Not in release Not in release Not in release Not in release
mplayer Not affected Not affected Not affected Not affected
vlc Not affected Not affected Not affected Not affected
kino Not in release Needs evaluation Needs evaluation Needs evaluation
mythtv Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libav Not in release Not in release Not in release Not in release
gst-libav1.0 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
oxide-qt Not in release Not in release Not in release Not in release
Show all 10 packages Show less packages

CVE-2016-10579

Medium priority
Not affected

Chromedriver is an NPM wrapper for selenium ChromeDriver. Chromedriver before 2.26.1 downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by...

2 affected packages

chromium-browser, oxide-qt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser Not affected
oxide-qt Not in release
Show less packages

CVE-2018-6126

Medium priority

Some fixes available 16 of 19

A precision error in Skia in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.

4 affected packages

chromium-browser, firefox, oxide-qt, thunderbird

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser Fixed
firefox Fixed
oxide-qt Not in release
thunderbird Fixed
Show less packages

CVE-2017-6888

Low priority

Some fixes available 3 of 31

An error in the "read_metadata_vorbiscomment_()" function (src/libFLAC/stream_decoder.c) in FLAC version 1.3.2 can be exploited to cause a memory leak via a specially crafted FLAC file.

6 affected packages

android, flac, praat, chromium-browser, mame, oxide-qt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
android Not in release Not in release Not in release Not in release
flac Not affected Not affected Not affected Fixed
praat Needs evaluation Needs evaluation Needs evaluation Needs evaluation
chromium-browser Not affected Not affected Not in release Not affected
mame Not affected Not affected Not affected Not affected
oxide-qt Not in release Not in release Not in release Not in release
Show less packages